Trust basics
- Read-only wallet analysis
- No seed phrase
- No private keys
- No custody
- No wallet approvals
- No swaps or trading actions
- HTTPS secured
- No tracking cookies by default
ShieldMendAI Safety Pledge
ShieldMendAI helps everyday holders understand holdings, profit/loss, tax lots, rewards, airdrops, unlocks, and possible sale outcomes using public wallet data.
This is a self-audit checklist, not a third-party certification or outside audit.
Backend API safety summary
The backend remains private behind Nginx. The public proxy only exposes the health check and API routes needed by the site.
/health and /api/*.
Invite verification happens server-side. Public pages must not list real or placeholder invite strings.
There is no public app release link on the website. Beta access remains gated.
Self-audit checklist
This checklist is maintained by the project team and should be reviewed before each public release.
Last updated: July 7, 2026. Site commit reviewed: f9a2b56. License: MIT.
No wallet connection, signing prompt, custody, approvals, swaps, or trading actions should be required for public site flows.
The beta page calls the server-side verification API and does not publish invite strings.
The static site should not add third-party measurement code, ad pixels, tracking cookies, or a cookie pop-up.
Outputs are estimates only. ShieldMendAI does not file taxes and does not replace a tax professional.
Estimates only. ShieldMendAI provides planning information for review. It is not tax, legal, accounting, financial, or investment advice. Confirm with a qualified tax professional before filing or making tax-sensitive decisions.